EnglishFrenchSpanish

Ad


OnWorks favicon

compartment - Online in the Cloud

Run compartment in OnWorks free hosting provider over Ubuntu Online, Fedora Online, Windows online emulator or MAC OS online emulator

This is the command compartment that can be run in the OnWorks free hosting provider using one of our multiple free online workstations such as Ubuntu Online, Fedora Online, Windows online emulator or MAC OS online emulator

PROGRAM:

NAME


compartment - secure program/service wrapper

SYNOPSIS


compartment [--cap CAPSET] [--chroot PATH] [--user USER] [--group GROUP] [--init PROGRAM]
[--verbose] [--quiet] [--fork] /full/path/to/program

DESCRIPTION


The Secure Compartment was designed to allow safe execution of priviliged and/or untrusted
executables and services. It has got all features possible included, which can be used to
minimize the risk of a trojanized or vulnerable program/service.

COMMANDLINE OPTIONS


--cap CAPSET
sets the defined CAPABILITY for the process. See the README file and the section
LIMITATIONS for more information and examples.

--chroot PATH
chroots to the PATH defined. It has to be a valid chroot environment. See the
README file for more information and examples.

--user USER
runs the program with uid/euid of USER

--group GROUP
runs the program with gid/egid of GROUP

--init PROGRAM
runs PROGRAM before running the untrusted program/service, e.g. to build a chroot
environment

--verbose
prints detailled information what compartment does.

--quit does not print syslog information about the use of compartment

--fork forks if everything was set up correctly, mother process will exit.

FEATURES


Linux Capabilities

supports all Linux capabilites
(see /usr/include/linux/capability.h and the README file)

Chrooting

supports a chroot setup

Privileges

supports running with defined user and/or group privileges

Setup Scripts

supports running of initial scripts
before running a program/service, e.g. to build a chroot environment.

LIMITATIONS


Currently the kernel does not allow capabilities on processes which are not running with
euid 0. Therefore compartment will exit with an error if --user and --cap is used
together.

Please note that this will change for the 2.4 kernel.

Use compartment online using onworks.net services


Free Servers & Workstations

Download Windows & Linux apps

  • 1
    Image Downloader
    Image Downloader
    Crawl and download images using
    Selenium Using python3 and PyQt5.
    Supported Search Engine: Google, Bing,
    Baidu. Keywords input from the keyboard
    or input from ...
    Download Image Downloader
  • 2
    Eclipse Tomcat Plugin
    Eclipse Tomcat Plugin
    The Eclipse Tomcat Plugin provides
    simple integration of a tomcat servlet
    container for the development of java
    web applications. You can join us for
    discussio...
    Download Eclipse Tomcat Plugin
  • 3
    WebTorrent Desktop
    WebTorrent Desktop
    WebTorrent Desktop is for streaming
    torrents on Mac, Windows or Linux. It
    connects to both BitTorrent and
    WebTorrent peers. Now there's no
    need to wait for...
    Download WebTorrent Desktop
  • 4
    GenX
    GenX
    GenX is a scientific program to refine
    x-ray refelcetivity, neutron
    reflectivity and surface x-ray
    diffraction data using the differential
    evolution algorithm....
    Download GenX
  • 5
    pspp4windows
    pspp4windows
    PSPP is a program for statistical
    analysis of sampled data. It is a free
    replacement for the proprietary program
    SPSS. PSPP has both text-based and
    graphical us...
    Download pspp4windows
  • 6
    Git Extensions
    Git Extensions
    Git Extensions is a standalone UI tool
    for managing Git repositories. It also
    integrates with Windows Explorer and
    Microsoft Visual Studio
    (2015/2017/2019). Th...
    Download Git Extensions
  • More »

Linux commands

Ad